VDB

GCVE-110-OSM-2026-6223

GCVE-110-OSM-2026-6223
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 18, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution. ENTRY dist/agent-flow.js (bin: dist/agent-flow.js) - Postinstall Script in package.json: ""postinstall": "node -e \"" PERSISTENCE - Startup Persistence in dist/agent-flow.js: ".profile" - Startup Persistence in dist/web/_next/static/chunks/255-eef1c758985c6eab.js: ".profile" - Startup Persistence in dist/web/_next/static/chunks/4bd1b696-8b20f5740c9f0351.js: ".profile" - Startup Persistence in dist/web/_next/static/chunks/framework-0b845277e4370f02.js: ".profile" DESTINATION - reconstructed: https://react.dev/errors/refresh:x-nextjs-rewritten-path (primary, reconstructed) in dist/web/_next/static/chunks/255-eef1c758985c6eab.js - reconstructed: https://react.dev/errors/null (reconstructed) in dist/web/_next/static/chunks/255-eef1c758985c6eab.js - reconstructed: https://github.com/syntax-tree/hast-util-to-jsx-runtime#cannot-parse-style-attribute (reconstructed) in dist/web/_next/static/chunks/255-eef1c758985c6eab.js - reconstructed: https://react.dev/errors/3 (reconstructed) in dist/web/_next/static/chunks/255-eef1c758985c6eab.js - custom-c2: react.dev (reconstructed) in dist/web/_next/static/chunks/255-eef1c758985c6eab.js - custom-c2: https://git.new/pathToRegexpError\x20for\x20info (plaintext) in dist/agent-flow.js - custom-c2: https://x-access-token: (plaintext) in dist/agent-flow.js - custom-c2: https://nextjs.org/docs/messages/failed-to-find-server-action (plaintext) in dist/web/_next/static/chunks/255-eef1c758985c6eab.js (+33 more) EXFIL - Fetch and Eval/Exec in dist/web/_next/static/chunks/app/page-244ac5b93c433840.js: "fetch("/api/config/worktrees/".concat(encodeURIComponent(g),"/run-tlc-exec" - Data Encoding for Exfiltration in dist/agent-flow.js: "encodeURIComponent(String(_0x2d6d0e))[_0x33fd56(0xbfc)](_0x4a7b9d,_0x3151dd);}fu..." - Data Encoding for Exfiltration in dist/web/_next/static/chunks/255-eef1c758985c6eab.js: "btoa(" - Dynamic C2 Endpoint Construction in dist/web/_next/static/chunks/255-eef1c758985c6eab.js: "function r(e){let t=5381;for(let r=0;r<e.length;r++)t=(t<<5)+t+e.charCodeAt(r)|0..." - Data Encoding for Exfiltration in dist/web/_next/static/chunks/4bd1b696-8b20f5740c9f0351.js: "encodeURIComponent(arguments[1]);for(var t=2;t<arguments.length;t++)n+="&args[]=..." - Data Encoding for Exfiltration in dist/web/_next/static/chunks/790-ff6d90911b0910f6.js: "encodeURIComponent(a)),r=n+i+1,a=""),i&&(n+=i,i=0)}return t.join("")+e.slice(r)}..." - Dynamic C2 Endpoint Construction in dist/web/_next/static/chunks/790-ff6d90911b0910f6.js: "function e(){var t,n,r,i,c,u,d=arguments[0],f=1,p=arguments.length,m=!1;for("boo..." - Data Encoding for Exfiltration in dist/web/_next/static/chunks/app/page-244ac5b93c433840.js: "encodeURIComponent(e.id),"/columns")).then(e=>e.json()).then(e=>{e.error||(T(e),..." (+5 more) OBFUSCATION - Obfuscation: augmented proxied array function replacements in dist/agent-flow.js - Obfuscation: function to array replacements in dist/agent-flow.js - Dynamic Base64 Decoding in dist/web/_next/static/chunks/255-eef1c758985c6eab.js: "atob(e[" - Obfuscation: function to array replacements in dist/web/_next/static/chunks/255-eef1c758985c6eab.js - Obfuscation: function to array replacements in dist/web/_next/static/chunks/4bd1b696-8b20f5740c9f0351.js - Obfuscation: function to array replacements in dist/web/_next/static/chunks/790-ff6d90911b0910f6.js - Obfuscation: function to array replacements in dist/web/_next/static/chunks/framework-0b845277e4370f02.js - Obfuscation: function to array replacements in dist/web/_next/static/chunks/main-efd91ad78e102d77.js (+15 more) ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in dist/web/_next/static/chunks/255-eef1c758985c6eab.js: "https://react.dev/errors/refresh:x-nextjs-rewritten-path" - Shell Command Execution in dist/agent-flow.js: "execSync(" - Indirect Function Constructor Access in dist/agent-flow.js: "['constructor']" - Platform Detection with Data Collection in dist/web/_next/static/chunks/255-eef1c758985c6eab.js: "JSON.stringify({id:S.id,bound:S.bound},l),null===s&&(s=new FormData),S=i++,s.set..." - Dynamic Code Execution in dist/web/_next/static/chunks/790-ff6d90911b0910f6.js: "exec(r)" - Clipboard Access in dist/web/_next/static/chunks/app/page-244ac5b93c433840.js: "navigator.clipboard.writeText" PAYLOAD FILES dist/web/_next/static/chunks/255-eef1c758985c6eab.js (+ dist/web/_next/static/chunks/790-ff6d90911b0910f6.js, dist/agent-flow.js) INDICATORS (IOCs) - ipv6: 7:: - urls: https://ast-grep.github.io/guide/quick-start.html, https://a, https://tailwindcss.com - domains: ast-grep.github.io, tailwindcss.com, github.com - sha256Hashes: 69867b0e19be1fb556d2e697f0f18f1de0363d1aa2de9d36754d5b107156357c - payloadFileHash: 8d5fd46879fd9033b5141bfb74d8d1bf067783689cb33e9ae1901988d5196308

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@rafaelsene01/agent-flow1.9.0 (affected)

References

advisory
vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›